tag

Htb

373 posts
rev

Sekure Decrypt

Sekure Decrypt: reverse the validation logic, model the transform, and recover the accepted input.

rev

Shuffleme

Shuffleme: trace the binary, isolate the validation routine, and invert it to recover the flag.

rev

Snakecode

Snakecode: reverse the validation logic, model the transform, and recover the accepted input.

rev

Tear Or Dear

Tear Or Dear: decompile the .NET logic, rebuild the check, and recover the accepted input.

rev

The Art of Reversing

The Art of Reversing: decompile the .NET logic, rebuild the check, and recover the accepted input.

rev

You Cant C Me

You Cant C Me: reverse the validation logic, model the transform, and recover the accepted input.

crypto

AHS512

AHS512: reconstruct the PRNG state from the leak, replay it, and recover the flag.

crypto

Arranged

Arranged: abuse the AES misuse, derive the missing key material, and decrypt the flag.

crypto

baby quick maffs

baby quick maffs: model the crypto leak, recover the missing secret, and decrypt the flag.

crypto

Bank-er-smith

Bank-er-smith: exploit the RSA structure, recover the missing secret, and decrypt the flag.

ai

Battle in OrlOn

Battle in OrlOn: shape the prompt path, bypass the model guard, and recover the target output.

crypto

BBGun06

BBGun06: exploit the RSA structure, recover the missing secret, and decrypt the flag.

crypto

Bloom Bloom

Bloom Bloom: abuse the AES misuse, derive the missing key material, and decrypt the flag.

crypto

Brainy's Chyper

Brainy's Chyper: exploit the RSA structure, recover the missing secret, and decrypt the flag.

ai

Death's Glance

Death's Glance: shape the prompt path, bypass the model guard, and recover the target output.

crypto

ElElGamal

ElElGamal: use the curve leak or invalid-curve path to recover the secret and decrypt the flag.

crypto

Fast Carmichael

Fast Carmichael: use the curve leak or invalid-curve path to recover the secret and decrypt the flag.

crypto

How The Columns Have Turned

How The Columns Have Turned: model the crypto leak, recover the missing secret, and decrypt the flag.

crypto

I know Mag1k

I know Mag1k: derive the XOR key stream, invert the transform, and recover the flag.

crypto

I'm gRoot

I'm gRoot: reduce the hash constraint to a small search, test candidates, and recover the flag.

crypto

Iced Tea

Iced Tea: abuse the AES misuse, derive the missing key material, and decrypt the flag.

web

Under Construction

Under Construction: exploit the SQL injection, extract the needed data, and reach the flag.

web

Jailbreak

Jailbreak: identify the broken request handling, prove control, and use it to recover the flag.